Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.252exploits catalogados
38.481CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.678Exploit-DB 24.485GitHub PoC 15.900VulnCheck XDB 9221Nuclei 4455Metasploit 3513✓ solo verificadosrecientespopularesriesgo
82.252 exploits
Exploit-DB✓ VexDay Proof
Hot Links SQL-PHP - 'news.php' SQL Injection
SQL injection vulnerability in Mr. CGI Guy Hot Links SQL-PHP 3 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Alstrasoft Forum - 'catid' SQL Injection
SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange allows remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Bonjour for Windows 1.0.4 - mDNSResponder Null Pointer Dereference Denial of Service
mDNSResponder in the Bonjour Namespace Provider in Apple Bonjour for Windows before 1.0.5 allows attackers to cause a de
23RIESGO
abrir ↗Metasploit300
Windows Media Encoder 9 wmex.dll ActiveX Buffer Overflow
Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9
50RIESGO
abrir ↗Metasploit500
BEA Weblogic Transfer-Encoding Buffer Overflow
Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 M
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Organization Chart 2 - Remote Code Execution
orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (applicati
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5.2.5 - Multiple functions 'safe_mode_exec_dir' / 'open_basedir' Restriction Bypass Vulnerabilities
PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
eXtrovert software Thyme 1.3 - 'pick_users.php' SQL Injection
SQL injection vulnerability in pick_users.php in the groups module in eXtrovert Thyme 1.3 allows remote attackers to exe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
D-Link DIR-100 1.12 - Security Bypass
The web proxy service on the D-Link DIR-100 with firmware 1.12 and earlier does not properly filter web requests with la
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Image Acquisition Logger ActiveX Control Arbitrary File Overwrite (1)
The Microsoft Windows Image Acquisition Logger ActiveX control allows remote attackers to force the download of arbitrar
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Image Acquisition Logger ActiveX Control Arbitrary File Overwrite (2)
The Microsoft Windows Image Acquisition Logger ActiveX control allows remote attackers to force the download of arbitrar
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Core 2.6.1 - SQL Column Truncation
wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpAdultSite CMS - 'results_per_page' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in as_archives.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
E-PHP B2B Trading Marketplace Script - 'listings.php' SQL Injection
SQL injection vulnerability in listings.php in E-Php B2B Trading Marketplace Script allows remote attackers to execute a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Silentum LoginSys 1.0 - Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in login.php in Silentum LoginSys 1.0.0 allows remote attackers to inject arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EsFaq 2.0 - 'idcat' SQL Injection
SQL injection vulnerability in questions.php in EsFaq 2.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebCMS Portal Edition - 'id' Blind SQL Injection
SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XRms 1.99.2 - 'starting' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XRms 1.99.2 - 'last_name' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XRms 1.99.2 - 'case_title' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XRms 1.99.2 - 'file_id' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XRms 1.99.2 - 'campaign_title' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XRms 1.99.2 - 'company_name' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XRms 1.99.2 - 'title' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir ↗Exploit-DB
Zen Cart < 1.3.8a - SQL Injection
Multiple SQL injection vulnerabilities in includes/classes/shopping_cart.php in Zen Cart 1.2.0 through 1.3.8a, when magi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XRms 1.99.2 - 'login.php?target' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XRms 1.99.2 - 'opportunity_title' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
eliteCMS 1.0 - 'page' SQL Injection
SQL injection vulnerability in index.php in eliteCMS 1.0 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CeleronDude Uploader 6.1 - 'account.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in account.php in Celerondude Uploader 6.1 allows remote attackers to inject ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IDevSpot BizDirectory 2.04 - 'page' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in BizDirectory 2.04 and earlier allows remote attackers to inject arbitrary we
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.